Glossary · Industrial cybersecurity
Authorization
German: Autorisierung
In industrial cybersecurity, authorization is the determination of which actions an authenticated user, device or system is permitted to perform. It is usually implemented through roles and permissions following the principle of least privilege.
- Cybersecurity
- Standards
In one sentence
Authorization decides which actions an authenticated user, device or system may perform, typically by roles and least privilege.
Example
On a palletizing robot, operators may start and stop production, maintenance technicians may jog axes in reduced speed, and only the safety engineer may change the configuration of the safety zones.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Cybersecurity: IEC 62443 covers this under the foundational requirement of use control. Permissions should match tasks, and privileged functions such as firmware updates or parameter changes need explicit rights.
- Machine safety: Access to operating modes and safety configuration is a safety measure as well as a security measure. A mode selector with a key and a role-based login serve the same purpose.
- Technical documentation: Describe roles in the manual together with the tasks they may perform and the qualification required. The role model in the documentation should match the one in the software.
- Evidence: Review permissions periodically, especially after staff changes, and after a remote access contract ends.
Authorization vs. authentication
Authentication answers who someone is. Authorization answers what they may do. Both must be in place: strong authentication with overly broad permissions still lets a single compromised account change safety parameters.